T09 · Insecure Skill Coding Practices
- Location
SKILL.md:37- Finding
Unvalidated API Origin Override Can Disclose the Bearer Credential
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 37-43
Vulnerability Type: Untrusted API endpoint configuration with credential forwarding
Risk Level: MediumVulnerable Code Snippet:
text ## Authentication All API requests require:Authorization: Bearer <SWARMRECALL_API_KEY>
text ## API Base URL `https://swarmrecall-api.onrender.com` (override with `SWARMRECALL_API_URL` if set)Technical Analysis
The Skill requires every API request to include
SWARMRECALL_API_KEYas a bearer credential while allowing the destination origin to be replaced through theSWARMRECALL_API_URLenvironment variable. It specifies no validation of the replacement URL's scheme, hostname, port, or trust status.Consequently, an attacker who can influence the Agent's environment can set the override to an attacker-controlled endpoint. When the Skill subsequently follows its authentication instructions, it may transmit both the bearer credential and user-provided knowledge-graph content to that endpoint.
This is an insecure configuration pattern rather than evidence of intentional credential theft. The intended default API uses HTTPS and the documented service domain, but the unrestricted override weakens that protection.
Attack Path
- An attacker, compromised launcher, or unsafe deployment configuration sets
SWARMRECALL_API_URLto an attacker-controlled URL, such ashttps://attacker.example. - The Agent loads the Skill and accepts that environment variable as the API base URL.
- The Agent performs an entity, relation, search, traversal, or validation request.
- Following the authentication requirement, it attaches
Authorization: Bearer <SWARMRECALL_API_KEY>. - The attacker's server records the bearer credential and any submitted knowledge-graph data.
- The attacker may use the captured credential against the legitimate SwarmRecall API to access or modify data avail ...[truncated 636 chars]
- An attacker, compromised launcher, or unsafe deployment configuration sets
- Remediation
View remediation
Remediation Suggestions
- Remove
SWARMRECALL_API_URLsupport if custom API origins are unnecessary. - Otherwise, validate the resolved URL before attaching credentials:
- Require the
httpsscheme. - Permit only an explicit hostname allowlist.
- Reject embedded credentials, unexpected ports, IP-literal hosts, redirects to other origins, and malformed URLs.
- Require the
- Attach
SWARMRECALL_API_KEYonly when the final request origin exactly matches a trusted origin. - Disable automatic cross-origin forwarding of the
Authorizationheader during redirects. - Require explicit user or administrator approval before enabling a non-default endpoint.
- Use separate, narrowly scoped credentials for development or self-hosted endpoints rather than reusing the production credential.
- Document that environment variables are security-sensitive configuration and must not be accepted from untrusted launchers or project-local environment files.
- If an untrusted override may already have been used, revoke and rotate the affected API key and review remotely stored knowledge for unauthorized access or modification.
- Remove
